EIP-2026-113745
PRE-CVEWordPress Plugin File Manager 3.0.1 - Cross-Site Request Forgery
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113745. PoCs published by David Vaartjes.
AI-analyzed exploit summary This is a functional CSRF exploit for the File Manager WordPress Plugin (v3.0.1) that allows arbitrary PHP file uploads via a crafted multipart/form-data request. The PoC demonstrates how an attacker can upload a malicious PHP file to the server by leveraging the lack of CSRF protection in the plugin's upload form.
Description
WordPress Plugin File Manager 3.0.1 - Cross-Site Request Forgery
Exploits (1)
This is a functional CSRF exploit for the File Manager WordPress Plugin (v3.0.1) that allows arbitrary PHP file uploads via a crafted multipart/form-data request. The PoC demonstrates how an attacker can upload a malicious PHP file to the server by leveraging the lack of CSRF protection in the plugin's upload form.